Techné AI · Free reference · Edition 3.0.0
Sectoral Regulation
How AI interacts with healthcare, financial-services and employment obligations; a guide to sector-specific sources and implementation questions.
On this page
An AI system can be subject to existing sector law even when no AI-specific statute applies. This chapter distinguishes binding requirements from agency guidance, voluntary frameworks, and proposals in selected US sectors. Status is reviewed as of 7 September 2026. See International, US State Laws, and EU AI Act for additional jurisdictional overlays.
Healthcare — device classification and change control
FDA’s current Predetermined Change Control Plan (PCCP) final guidance is dated August 2025, not December 2024. It provides nonbinding recommendations for marketing submissions involving AI-enabled device software functions. FDA reviews a proposed PCCP as part of the relevant marketing submission; changes implemented consistently with the authorised plan can avoid an additional marketing submission. This is not a blanket exemption for every model update.1
The guidance describes three components:
- Description of Modifications — the planned changes.
- Modification Protocol — the methods for developing, validating, and implementing them.
- Impact Assessment — the expected effects of those changes.
Classification comes first. FDA issued its current Clinical Decision Support Software final guidance in January 2026. Certain functions satisfy the statutory non-device exclusion; other decision-support functions remain subject to device regulation. A product being described as “clinical AI” does not resolve that question. FDA’s January 2025 AI-device lifecycle and marketing-submission guidance is still listed as draft, which should not be described as a final rule.23
Other healthcare duties may apply independently of FDA classification. 45 CFR 92.210, not 42 CFR Part 92, addresses covered entities’ use of patient-care decision-support tools. Its text prohibits discrimination and requires reasonable efforts to identify specified risk factors and mitigate resulting discrimination risks. Applicability depends on the covered entity and activity; this is not a universal rule for every non-device AI product. Check relevant court orders and current HHS implementation before relying on a particular Section 1557 provision.4
Financial services
The OCC, Federal Reserve, and FDIC issued revised interagency model-risk-management guidance on 17 April 2026, replacing the 2011 guidance. OCC Bulletin 2026-13 expressly rescinds OCC Bulletin 2011-12 and other listed guidance. The old SR 11-7/OCC 2011-12 framework should therefore not be presented as the unchanged current instrument.5
The revised guidance:
- Addresses model development, use, validation, monitoring, governance, and third-party products.
- Is most relevant to banks with more than $30 billion in assets, although smaller banks with significant model-risk exposure may also find it relevant.
- Excludes generative and agentic AI from its scope. It is not an AI-specific supervisory standard covering every bank AI deployment.
- Does not establish enforceable standards or prescriptive requirements; the bulletin distinguishes supervisory guidance from law.
Separately, the CFPB’s 26 September 2025 AI Compliance Plan implements OMB M-25-21 for the Bureau’s own use of AI. It is not a new supervisory framework governing lenders’ AI in lending, servicing, and collections.6
Existing substantive law must be assessed on its own terms. For example, ECOA and Regulation B govern covered credit activity, including discrimination and adverse-action notification requirements. Using a complex model does not itself remove those obligations. Consumer-reporting, housing-lending, privacy, and other requirements need their own applicability analysis.7
Employment
Title VII, the ADA, and the ADEA can apply to employment tests and selection procedures, including computer-mediated tools. The relevant question is the effect and use of a procedure, not whether a vendor markets it as AI. EEOC’s published discussion addresses discriminatory exclusion, job-related validation, and disability accommodation. A vendor’s claims do not substitute for the employer’s assessment of its own use.8
State and local duties are additional and differ in scope. See US State Laws for NYC Local Law 144, Illinois HB 3773, and Colorado’s replacement law, SB 26-189, whose principal duties begin on 1 January 2027.
Practical controls include:
- Determine whether a hiring or promotion tool is a covered automated employment decision tool under NYC’s law before applying its bias audit, publication, and notice requirements. These requirements do not attach to every New York City hiring process.
- Evaluate job relevance, selection outcomes, and validation obligations under the applicable employment-law framework. Do not treat the Uniform Guidelines as a universal requirement to commission the same study for every tool.
- Provide a process to request reasonable accommodations and assess tools that may screen out qualified applicants with disabilities.
- Track candidate and employee notices separately for each applicable state or local law.
This chapter does not rely on an unverified date for the withdrawal of earlier agency AI guidance; changes in guidance should not be conflated with repeal of underlying statutes.
Consumer protection — FTC
Section 5 of the FTC Act prohibits unfair or deceptive acts or practices within the Commission’s jurisdiction. AI marketing, product representations, and data practices therefore require analysis under existing consumer-protection law; an “AI” label neither establishes a violation nor creates an exemption.9
The FTC began enforcing the TAKE IT DOWN Act’s platform obligations on 19 May 2026. Covered platforms must provide the prescribed notice-and-removal process for qualifying nonconsensual intimate imagery, including qualifying synthetic imagery, and comply with the 48-hour removal requirement after a valid request, alongside the Act’s other duties. This is not a general requirement to remove any allegedly harmful AI output within 48 hours.10
Useful governance measures include keeping substantiation for performance claims, checking whether actual data use matches representations, and assigning complaint and removal-request owners. NIST AI RMF can help organise that work; use of the framework is not a legal safe harbour.
Telecommunications
The FCC’s 8 February 2024 declaratory ruling confirms that AI technologies generating human voices fall within the TCPA’s restrictions on artificial or prerecorded voices. The relevant calls generally require prior express consent unless an emergency-purpose exception or applicable exemption applies; telemarketing and other call-specific requirements must also be checked. The ruling is not a ban on every use of synthetic speech.11
The US Federal chapter addresses subsequent executive-branch directions concerning AI disclosure. A direction to consider or initiate rulemaking should not be represented as an already-operative FCC disclosure standard.
Critical infrastructure
NIST is developing an AI RMF Profile for Trustworthy AI in Critical Infrastructure. Its 2026 concept note describes a work programme, not a completed profile or a binding sector regulation.12
Operators should separately identify the actual cybersecurity, safety, reliability, procurement, and incident-reporting requirements that apply to their facilities and activities. Do not assume that every sector rule has acquired an AI-specific provision, or that applying a voluntary NIST profile satisfies those obligations.
Other sector overlays
- Education — FERPA restricts disclosure of personally identifiable information from education records at covered institutions. Vendor access must fit consent or an applicable exception and its conditions; use of an AI service is not itself an exception.13
- Transportation — NHTSA’s Standing General Order requires specified manufacturers and operators to report certain crashes involving automated driving systems or SAE Level 2 advanced driver-assistance systems. It is not a reporting mandate for every vehicle containing AI.14
- Defence — DoD Directive 3000.09, effective 25 January 2023, governs specified autonomous and semi-autonomous weapon systems, including human judgment, testing, and review requirements. Its scope and exceptions matter; it is not a general commercial AI law.15
- Insurance — NAIC adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023. It describes expectations including risk-based written AI-system programmes and compliance with existing insurance law. The model bulletin is not self-executing nationwide: identify each relevant state’s adoption, modifications, and supervisory requirements.16
How to navigate sectoral overlap
An organisation may face a product regime, sector requirements, employment or consumer-protection law, and state AI duties simultaneously. A useful compliance register should:
- Map applicability for each system, legal entity, jurisdiction, and intended use.
- Separate authority types: statute or regulation, supervisory guidance, draft, voluntary framework, and contractual requirement.
- Reuse evidence where appropriate, while retaining regime-specific analyses, submissions, notices, and records. Conformity with a management-system standard does not establish compliance with every sector rule.
- Assign owners and review triggers for model changes, new uses, incidents, and changes in law.
- Seek specialist or regulator input where appropriate, particularly when device classification, a required submission, or an ambiguous supervisory scope affects deployment.
Footnotes
-
FDA. Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions (final guidance, August 2025). ↩
-
FDA. Clinical Decision Support Software (final guidance, January 2026). ↩
-
eCFR. 45 CFR 92.210: Nondiscrimination in the use of patient care decision support tools. ↩
-
OCC. Bulletin 2026-13: Revised Guidance on Model Risk Management (17 April 2026). ↩
-
CFPB. AI Compliance Plan for OMB M-25-21 (26 September 2025); Artificial Intelligence at the CFPB. ↩
-
CFPB. 12 CFR Part 1002: Equal Credit Opportunity Act (Regulation B). ↩
-
FTC. FTC Begins Enforcing the TAKE IT DOWN Act (19 May 2026). ↩
-
NIST. Concept Note: AI RMF Profile for Trustworthy AI in Critical Infrastructure. ↩
-
US Department of Education. Privacy and Data Sharing. ↩
-
DoD. Directive 3000.09: Autonomy in Weapon Systems (25 January 2023). ↩
-
NAIC. Members Approve Model Bulletin on Use of AI by Insurers (4 December 2023). ↩
This free handbook is a dated educational reference, not a determination of your organization's obligations. Check the source, jurisdiction and role before applying a requirement. For working documents, see TalentSight Intelligence and BoardSight Intelligence.